Draftly
Features Compare Pricing FAQ Start drafting

DRAFTLY · LEGAL

Privacy Policy

Effective May 16, 2026. Last updated May 16, 2026.

On this page

  • 1. The short version
  • 2. Who we are
  • 3. What we collect
  • 4. How we use it
  • 5. Who we share it with
  • 6. Cookies and local storage
  • 7. How long we keep it
  • 8. How we protect it
  • 9. Your rights
  • 10. Children
  • 11. International users
  • 12. Changes to this policy
  • 13. Contact

1. The short version

Draftly is a CAD application built for working drafters. We collect the minimum information needed to run the product: an email address if you create an account, the drawings you save to the cloud if you opt into sync, and basic technical information so the app keeps working. We do not sell your data, we do not run ad networks, and we do not train AI models on your drawings.

2. Who we are

Draftly is operated by Tyler Thompson (doing business as "Draftly"). When this policy says "we," "us," or "Draftly," it refers to that operator. You can reach us at hello@draftlycad.com.

3. What we collect

Information you give us

  • Account information. When you create an account, we collect your email address and a password (stored as a salted hash — we never see the plaintext). You may also provide an optional display name.
  • Drawings and project content. If you opt into cloud sync, the drawings, layers, dimensions, and other CAD artifacts you create are stored on our servers so they're available across your devices.
  • Billing information. Paid plans are processed through Apple's App Store, Google Play, or RevenueCat's web checkout. Draftly never sees your full card number. We receive a subscription token and the entitlement status (active, expired, in trial).
  • Support correspondence. If you email us we keep the thread so we can follow up.

Information we collect automatically

  • Device identifiers. A randomly generated device ID so a single account can sync across machines without collisions. This is not a hardware fingerprint.
  • Diagnostic information. Crash logs and basic error telemetry so we can fix what's broken. This excludes drawing contents.
  • Approximate IP address. Recorded transiently by our hosting providers for abuse prevention and routing. We don't build user profiles from it.

Information from third parties

  • Single sign-on providers. If you sign in with Google (or, in the future, Apple or Microsoft), we receive the email address and basic profile information that provider returns. We do not request access to your contacts, calendar, or other services.

4. How we use it

  • To operate the app: authenticate you, sync your drawings, and deliver the features you signed up for.
  • To bill you accurately and provision the entitlements you've paid for.
  • To send transactional email — sign-in confirmations, password resets, receipts, and important account notices.
  • To fix bugs and improve performance, using aggregated diagnostic data.
  • To respond to support requests.
  • To comply with the law when we have a legal obligation to do so.

We do not use your drawings or account data to train machine-learning or AI models. We do not sell your personal information. We do not share it with advertisers.

5. Who we share it with

We use a small set of vendors to operate the product. Each one receives only the data needed to do its job, under a contract that restricts its use.

  • Supabase — authentication and primary database (US-hosted Postgres). Stores your account record and, if sync is on, your drawings.
  • Cloudflare — content delivery, DNS, and static hosting for draftlycad.com and the in-browser app.
  • Render — backend API hosting (the service that accepts and serves drawing sync snapshots).
  • SendGrid (Twilio) — transactional email delivery for sign-in confirmations, password resets, and receipts.
  • RevenueCat — subscription entitlement management across Apple, Google, and web. Receives a user identifier so it can match purchases to your account.
  • Apple App Store / Google Play — payment processing on mobile. Their privacy practices govern the payment itself.
  • Google Identity — when you sign in with Google.

We may also share information when required by law (subpoena, court order, lawful government request), to defend our legal rights, or to protect the safety of users. If Draftly is ever acquired or transferred, account data may be transferred with the business — we'll notify you by email before that happens.

6. Cookies and local storage

On the marketing site at draftlycad.com, we use a minimal first-party cookie set — only what's needed for the Cloudflare edge to route requests. We do not use third-party advertising cookies.

Inside the application at draftlycad.com/app/, we store your session token, your unit and theme preferences, and a local cache of your drawings in your browser's local storage. You can clear that at any time from your browser's site settings.

7. How long we keep it

  • Account data: kept while your account is active. When you delete your account, we delete your authentication record and drawings within 30 days, except where we're required to keep records for tax or anti-fraud purposes.
  • Billing records: retained for the period required by applicable tax law (typically 7 years in the US).
  • Diagnostic logs: typically rotated within 30 days.

8. How we protect it

  • Passwords are stored as bcrypt-style salted hashes — we never see the plaintext.
  • Traffic between your device and our servers uses TLS 1.2 or higher.
  • Data at rest in Supabase is encrypted.
  • Access to production data is restricted and audited.

No service is 100% secure. If we ever experience a breach that affects your data, we'll notify you and the appropriate regulators as the law requires.

9. Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you.
  • Correct information that's inaccurate.
  • Delete your account and personal information.
  • Export your drawings and account data in a portable format.
  • Object to certain processing, or withdraw consent where processing is based on consent.

You can exercise any of these rights from Settings inside the app ("Export my data", "Delete account"), or by emailing hello@draftlycad.com. We'll respond within 30 days.

California residents. Under the CCPA you also have the right not to be discriminated against for exercising these rights. We do not sell personal information.

EEA, UK, and Swiss residents. Our legal bases for processing under the GDPR are: contract (operating the service you signed up for), legitimate interest (improving the product and preventing abuse), legal obligation, and consent (where we ask for it). You have the right to lodge a complaint with your local supervisory authority.

10. Children

Draftly is not directed to children under 13, and we do not knowingly collect information from them. If you believe a child has provided us with personal information, contact us and we'll delete it.

11. International users

Draftly is operated from the United States. If you use the product from outside the US, you understand that your information will be transferred to and processed in the US, where data-protection law may differ from your home jurisdiction.

12. Changes to this policy

We may update this policy as the product evolves. When we make a material change we'll update the "Last updated" date at the top and, for substantial changes, notify you by email or an in-app notice before the change takes effect.

13. Contact

Questions about this policy or about your data? hello@draftlycad.com.

© 2026 Draftly. Real CAD. Without the tax.

Home Privacy Terms Open app